Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,963 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
39,286 results · page 115 of 786
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2026-27851 | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. | CRITICAL 9.1EPSS 0.41% | 12 May 2026 |
| CVE-2026-8072 | Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. | CRITICAL 9.2EPSS 0.15% | 12 May 2026 |
| CVE-2026-7428 | Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative… | CRITICAL 9.2EPSS 0.24% | 12 May 2026 |
| CVE-2026-41551 | A vulnerability has been identified in ROS# (All versions < V2.2.2). | CRITICAL 9.3EPSS 0.49% | 12 May 2026 |
| CVE-2026-25787 | This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. | CRITICAL 9.3EPSS 0.37% | 12 May 2026 |
| CVE-2026-25786 | This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. | CRITICAL 9.3EPSS 0.37% | 12 May 2026 |
| CVE-2025-6577 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. | CRITICAL 9.8EPSS 0.26% | 12 May 2026 |
| CVE-2026-41872 | "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. | CRITICAL 9.1EPSS 0.16% | 12 May 2026 |
| CVE-2026-34263 | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and… | CRITICAL 9.6EPSS 0.61% | 12 May 2026 |
| CVE-2026-34260 | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL statements through user-controlled input. | CRITICAL 9.6EPSS 0.47% | 12 May 2026 |
| CVE-2026-45321 | TanStack Unspecified Vulnerability | KEVCRITICAL 9.6EPSS 2.34% | 12 May 2026 |
| CVE-2026-43914 | Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. | CRITICAL 9.8EPSS 0.29% | 11 May 2026 |
| CVE-2026-43900 | Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. | CRITICAL 9.3EPSS 0.31% | 11 May 2026 |
| CVE-2026-43899 | Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). | CRITICAL 9.6EPSS 0.33% | 11 May 2026 |
| CVE-2026-42882 | Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. | CRITICAL 9.4EPSS 0.55% | 11 May 2026 |
| CVE-2026-42869 | Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. | CRITICAL 10.0EPSS 0.44% | 11 May 2026 |
| CVE-2026-42864 | Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]). | CRITICAL 9.9EPSS 0.27% | 11 May 2026 |
| CVE-2026-42858 | The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. | CRITICAL 9.9EPSS 0.37% | 11 May 2026 |
| CVE-2026-38567 | HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. | CRITICAL 9.8EPSS 0.50% | 11 May 2026 |
| CVE-2026-7813 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. | CRITICAL 9.4EPSS 0.46% | 11 May 2026 |
| CVE-2026-44643 | Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. | CRITICAL 9.3EPSS 0.48% | 11 May 2026 |
| CVE-2026-42613 | Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. | CRITICAL 9.4EPSS 0.94% | 11 May 2026 |
| CVE-2026-42607 | Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. | EXPLOITCRITICAL 9.1EPSS 3.94% | 11 May 2026 |
| CVE-2026-35157 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. | CRITICAL 9.8EPSS 0.32% | 11 May 2026 |
| CVE-2021-47940 | WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. | CRITICAL 9.3EPSS 0.40% | 10 May 2026 |
| CVE-2021-47936 | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. | CRITICAL 9.3EPSS 0.66% | 10 May 2026 |
| CVE-2021-47933 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. | CRITICAL 9.3EPSS 0.59% | 10 May 2026 |
| CVE-2021-47932 | WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. | CRITICAL 9.3EPSS 0.40% | 10 May 2026 |
| CVE-2021-47923 | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. | CRITICAL 9.3EPSS 0.42% | 10 May 2026 |
| CVE-2026-6722 | As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution. | CRITICAL 9.5EPSS 0.89% | 10 May 2026 |
| CVE-2026-42601 | This config is exported as environment variables when archive plugins run, allowing injection of arbitrary tool arguments to achieve RCE. | CRITICAL 9.3EPSS 0.40% | 9 May 2026 |
| CVE-2026-42571 | From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escalation vulnerability affecting Pelican's Web User Interface (WebUI). | CRITICAL 9.0EPSS 0.32% | 9 May 2026 |
| CVE-2026-42569 | Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. | CRITICAL 9.4EPSS 1.17% | 9 May 2026 |
| CVE-2026-42560 | Any application that trusts token.User.ID as the stable account key can end up mixing or fully merging unrelated Patreon users, which can lead to cross-account access, privilege confusion, and subscription-state leakage. | CRITICAL 9.1EPSS 0.42% | 9 May 2026 |
| CVE-2026-6665 | A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow. | CRITICAL 9.8EPSS 0.37% | 9 May 2026 |
| CVE-2026-44313 | Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the fetchTitleAndHeaders function allows authenticated users to make arbitrary HTTP requests to internal services due to insufficient URL validation that only checks for… | CRITICAL 9.1EPSS 0.29% | 9 May 2026 |
| CVE-2026-42556 | From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. | CRITICAL 9.0EPSS 0.26% | 8 May 2026 |
| CVE-2026-42454 | Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed via ssh2.Client.exec() on remote managed servers without any… | CRITICAL 9.9EPSS 0.65% | 8 May 2026 |
| CVE-2026-42354 | From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. | CRITICAL 9.8EPSS 0.62% | 8 May 2026 |
| CVE-2026-42302 | From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). | CRITICAL 9.8EPSS 0.72% | 8 May 2026 |
| CVE-2026-42298 | Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a… | CRITICAL 9.8EPSS 0.50% | 8 May 2026 |
| CVE-2026-42287 | Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data theft, or system destruction. | CRITICAL 10.0EPSS 0.25% | 8 May 2026 |
| CVE-2026-42193 | This allows an unauthenticated attacker to spoof SNS events to trigger workflow automations, unsubscribe contacts, manipulate email delivery metrics, and potentially exhaust billing credits. | CRITICAL 9.1EPSS 0.13% | 8 May 2026 |
| CVE-2026-42160 | Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. | CRITICAL 10.0EPSS 0.25% | 8 May 2026 |
| CVE-2026-8178 | Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. | CRITICAL 9.2EPSS 0.57% | 8 May 2026 |
| CVE-2026-42072 | Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. | CRITICAL 9.8EPSS 0.44% | 8 May 2026 |
| CVE-2026-38360 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post()… | CRITICAL 9.8EPSS 5.98% | 8 May 2026 |
| CVE-2026-41070 | openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. | CRITICAL 10.0EPSS 0.44% | 8 May 2026 |
| CVE-2026-44498 | Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. | CRITICAL 9.2EPSS 0.28% | 8 May 2026 |
| CVE-2026-44497 | ZEBRA is a Zcash node written entirely in Rust. | CRITICAL 9.3EPSS 0.19% | 8 May 2026 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.